← לוח פגיעויות

CVE-2020-8840

קריטית 9.8

תיאור (מקור, אנגלית)

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-502

מוצרים מושפעים

fasterxml: jackson-databind; debian: debian linux; netapp: oncommand api services; netapp: oncommand workflow automation; netapp: service level manager; netapp: steelstore cloud integrated storage; huawei: oceanstor 9000 firmware; huawei: oceanstor 9000; oracle: global lifecycle management opatch

קישורים